GuidesARCHITECTURE
Free CORS proxy options compared
A free CORS proxy fetches a cross-origin resource server-side and returns it with the headers the browser demands. The options differ sharply in limits, credentials handling, and how much you have to run yourself, and this page compares the ones that are actually alive.
When a free proxy is the right call
A proxy earns its place when the target API is not yours: third-party public endpoints that send no CORS headers, prototypes that need data before infrastructure exists, and client-side apps with no backend of their own. The proxy makes the cross-origin call where no browser policy applies, then re-serves the response with permissive headers.
When you control the target API, skip the intermediary and fix its CORS response headers directly. Anything between your browser and your own server is a needless hop that can read every payload. Managed proxy or your own backend walks through that decision in full.
The options at a glance
| Option | How it works | Free tier limits | Credentials policy | Best for |
|---|---|---|---|---|
| cors.dev (anonymous) | Hosted prefix proxy for any public API host | Keyless; fair-use rate limits; 1 MiB, 10 s upstream cap | Never forwards cookies or Authorization | Keyless GETs against public APIs |
| CORS Anywhere (self-host) | Your own Node.js proxy server | Your infrastructure; public demo is rate limited and opt-in | Cookies blocked by default; configurable in code | Full control when you can run a server |
| corsproxy.io | Hosted proxy with API key | 10,000 requests and 1 GB bandwidth per month | Does not forward cookies or Authorization | Arbitrary hosts under a monthly free quota |
| allorigins.win | Hosted community proxy, no account | No published limits; availability is intermittent | Forwards what you send; operator sees traffic | Quick one-off fetches, demos |
| Corsfix | Hosted proxy with API key | Free trial; paid plans from $5/month, Lite $29/year | API key required to call the proxy | Production traffic with paid headroom |
cors.dev
cors.dev is a public CORS proxy for browser apps calling public JSON, XML, HTML, CSV and other text APIs. Prefix the target URL and the response comes back with the headers your origin needs. Anonymous use needs no API key, no signup and no registered origin, works from file: pages and curl too, and covers GET and HEAD requests.
const response = await fetch(
'https://proxy.cors.dev/https://api.frankfurter.dev/v1/latest?base=EUR',
);
const rates = await response.json();Anonymous requests reach any public HTTPS host, GET and HEAD only; hand-picked providers are featured at GET https://cors.dev/api/catalog. Responses are capped at 1 MiB with a 10-second upstream deadline, redirects are followed automatically, and cookies and Authorization headers are never forwarded. Anonymous use has fair-use rate limits with no daily request quota, and an account with Google sign-in adds Connections: saved allowed origins and hosts, publishable project keys, and a per-key activity view. Managed access has separate trial and paid limits.
CORS Anywhere
CORS Anywhere is the open-source Node.js package the hosted-proxy genre grew from, and self-hosting it is the classic cors-anywhere alternative to depending on someone else's server. Your server makes the cross-origin request where no browser check applies, then adds CORS headers to the response. Behavior is configured in code: host whitelists, rate limiting, requireHeader, and redirectSameProtocol. Cookies are not forwarded by default, and the proxy places no restrictions on request methods.
const corsAnywhere = require('cors-anywhere');
const host = '0.0.0.0';
const port = 8080;
corsAnywhere
.createServer({
originWhitelist: ['https://your-site.com'],
requireHeader: ['origin', 'x-requested-with'],
removeHeaders: ['cookie', 'cookie2'],
})
.listen(port, host, () => {
console.log(`CORS Anywhere running on ${host}:${port}`);
});
// Clients call: http://localhost:8080/https://api.example.com/dataThe public demo at cors-anywhere.herokuapp.com was locked down in February 2021 after sustained abuse. Proxying through it requires visiting the /corsdemo page first and clicking "Request temporary access to the demo server" for temporary opt-in access, and the demo is rate limited to 50 requests per hour and meant for development only.
// Requires visiting https://cors-anywhere.herokuapp.com/corsdemo first
// and requesting temporary access. Demo limit: 50 requests per hour.
const response = await fetch(
'https://cors-anywhere.herokuapp.com/https://api.example.com/data',
);Visit cors.dev vs CORS Anywhere for a side by side breakdown of limits and a before and after migration snippet.
corsproxy.io
corsproxy.io is a hosted proxy that requires a free account and an API key. The target URL goes in the url parameter, percent-encoded, alongside your key.
const target = encodeURIComponent('https://api.example.com/data');
const response = await fetch(
`https://corsproxy.io/?key=YOUR_API_KEY&url=${target}`,
);
// Free tier: 10,000 requests and 1 GB bandwidth per month.The free tier allows up to 10,000 requests and 1 GB of bandwidth per month. The service is designed not to forward cookies or Authorization headers to target servers.
cors.dev accepts the same ?url= syntax without a key, so moving is a host swap. Review limits and the migration snippet on the cors.dev vs corsproxy.io comparison page.
allorigins.win
allorigins.win is a free community-run proxy with no account and no API key. It exposes two forms: /raw?url= returns the target response body as-is, and /get?url= returns a JSON wrapper with the response in a contents field plus status metadata. Target URLs are percent-encoded.
// Raw: response body passed through as-is
const raw = await fetch(
'https://api.allorigins.win/raw?url=https%3A%2F%2Fapi.example.com%2Fdata',
);
// Wrapped: JSON with a contents field plus status metadata
const wrapped = await fetch(
'https://api.allorigins.win/get?url=https%3A%2F%2Fapi.example.com%2Fdata',
);
const { contents } = await wrapped.json();There are no published limits, but availability is intermittent: during verification for this page it returned successful responses as well as 520 and 522 origin errors within the same hour. Treat it as a convenience for one-off fetches and demos, not a dependency.
/raw?url= calls work on cors.dev with a host swap; /get callers drop the JSON wrapper. Check cors.dev vs allOrigins for limits and the before and after migration snippet.
Corsfix
Corsfix is a hosted proxy aimed at production use. The target URL goes after https://proxy.corsfix.com/? and requests authenticate with an API key.
const response = await fetch(
'https://proxy.corsfix.com/?https://api.example.com/data',
{ headers: { Authorization: 'Bearer YOUR_API_KEY' } },
);
// Free trial, then paid plans from $5/month; Lite $29/year for text data.There is a free trial ("try for $0", no credit card required). Paid plans start at $5 per month (Hobby: unlimited requests, 3 concurrent users, 60 RPM per user, 25 GB bandwidth) and run to $19 per month. A Lite plan at $29 per year covers text data such as JSON APIs and HTML with unlimited requests and bandwidth, 600 RPM shared across your users, and up to 1 MB per response.
Never route secrets through a public proxy
Every proxy operator can observe the traffic that passes through their service, whether that operator is a hosted provider or whoever runs a public CORS Anywhere instance you found in a forum thread. A request through a proxy is a request the operator can read, log, and replay.
Route public data only through any public proxy. API secrets, tokens, session cookies, and private user data belong on infrastructure you control, full stop. The cors.dev free tier rejects requests carrying cookies or an Authorization header. Managed access supports explicit Authorization headers, but never forwards browser cookies or hides private credentials in frontend code.
Get started with cors.dev
For keyless GET and HEAD calls to any public API there is nothing to set up: prefix the URL and fetch. The docs cover request syntax and limits, and the playground lets you test a live URL without writing code.
For write methods and authenticated APIs, managed access adds POST/PUT/PATCH/DELETE on public HTTPS hostnames enabled on your Connection, explicit Authorization and custom API headers, 1 MiB request bodies, and 6 MiB responses within 10 seconds. The trial includes 1,000 requests total over 7 days; Pro costs $5/month for 500,000 requests per monthly billing period. Keep private API credentials on your backend.
Good questions.
Is a free CORS proxy safe to use?
For public data, yes, with the caveat that the operator can observe everything you route through it. Never send secrets, tokens, cookies, or private user data through any public proxy. The cors.dev free tier rejects cookies and Authorization headers; managed access supports explicit Authorization headers but does not make frontend secrets private.
What is the best cors-anywhere alternative?
If you can run a Node.js server, self-hosting CORS Anywhere itself gives you full control with whitelist and rate-limit configuration in code. If you cannot, a hosted proxy like cors.dev (keyless, any public host) or corsproxy.io (API key, monthly free quota) removes the infrastructure burden.
Why does cors-anywhere.herokuapp.com ask me to visit /corsdemo first?
The public demo was locked down in February 2021 after abuse. Visiting /corsdemo and requesting temporary access opts you in for a limited time, and the demo is rate limited to 50 requests per hour and intended for development only. For anything serious, self-host the package.
Are free CORS proxies reliable enough for production?
Community proxies like allorigins.win publish no limits and show intermittent availability, so they fit demos rather than production traffic. Hosted services with defined tiers (cors.dev, corsproxy.io, Corsfix) publish limits you can design around, and paid plans buy headroom when free quotas run out.
Which upstream hosts can the cors.dev free tier reach?
Any public HTTPS host on port 443 for GET and HEAD requests. Private networks, IP literals and credential-bearing URLs are rejected, and every hop, redirects included, must resolve to public addresses before it is fetched. A hand-picked starter list is available at GET https://cors.dev/api/catalog.